HIPAA The Omnibus Rule 5 — Questions and Answers
Question 1: Under the Omnibus Rule, which of the following is a permissible use of PHI for health care operations WITHOUT individual authorization?
- Selling PHI to a pharmaceutical company for drug marketing
- Sharing PHI with a sister covered entity for joint quality improvement activities (Correct answer)
- Disclosing PHI to an employer for workplace wellness incentive tracking
- Providing PHI to a data broker for analytics resale
Correct answer: Sharing PHI with a sister covered entity for joint quality improvement activities
Covered entities that are under common ownership or control may share PHI for joint healthcare operations activities such as quality improvement without individual authorization.
Question 2: When the Omnibus Rule refers to 'remuneration' in the context of the sale of PHI, which of the following is generally excluded from this definition?
- Payment made to a covered entity for a list of patients for a pharmaceutical marketing campaign
- Reasonable costs of preparing and transmitting PHI for a permitted disclosure (Correct answer)
- A flat fee paid to a covered entity for a de-identified data set
- Revenue generated from a health information exchange charged to third parties
Correct answer: Reasonable costs of preparing and transmitting PHI for a permitted disclosure
Reasonable preparation and transmission costs for permissible disclosures are excluded from the definition of remuneration under the Omnibus Rule's sale-of-PHI prohibition.
Question 3: Under the Omnibus Rule, what must a business associate agreement (BAA) include regarding subcontractors?
- A list of all approved subcontractors the business associate may use
- A provision requiring the business associate to enter into BAAs with its subcontractors (Correct answer)
- A prohibition on the business associate using any subcontractors who handle PHI
- A requirement that subcontractors be certified by HHS before handling PHI
Correct answer: A provision requiring the business associate to enter into BAAs with its subcontractors
The Omnibus Rule requires that BAAs include a provision obligating business associates to enter into compliant BAAs with any subcontractors who create, receive, maintain, or transmit PHI.
Question 4: Under the Omnibus Rule, how did the definition of 'workforce' change with respect to HIPAA compliance obligations?
- Workforce was narrowed to include only full-time employees of covered entities
- Volunteers and trainees were excluded from the workforce definition to reduce covered entities' burden
- The workforce definition was expanded to explicitly include volunteers and trainees under HIPAA obligations (Correct answer)
- Independent contractors were newly classified as business associates rather than workforce members
Correct answer: The workforce definition was expanded to explicitly include volunteers and trainees under HIPAA obligations
The Omnibus Rule confirmed that the workforce definition includes volunteers, trainees, and other persons under the direct control of a covered entity.
Question 5: A hospital sends a patient's PHI to a law firm to defend against a malpractice lawsuit. Under the Omnibus Rule, how is the law firm classified?
- A covered entity because it handles PHI regularly
- A business associate because it receives PHI to perform services on the hospital's behalf (Correct answer)
- A subcontractor of the hospital's privacy officer
- Exempt from HIPAA because legal proceedings are excluded
Correct answer: A business associate because it receives PHI to perform services on the hospital's behalf
A law firm that receives PHI to perform legal services on behalf of a covered entity is considered a business associate and must sign a BAA.
Question 6: Under the Omnibus Rule, which of the following statements about the enforcement of civil monetary penalties (CMPs) is accurate?
- Business associates cannot be subject to CMPs — only covered entities can be fined
- HHS may only impose CMPs if the covered entity fails to correct the violation within 30 days
- Business associates are now directly subject to CMPs for HIPAA violations (Correct answer)
- CMPs may only be imposed after a criminal conviction has been obtained
Correct answer: Business associates are now directly subject to CMPs for HIPAA violations
The Omnibus Rule made business associates directly subject to civil monetary penalties for HIPAA violations, in addition to covered entities.
Question 7: Under the Omnibus Rule, a covered entity discovers an impermissible disclosure of PHI by a workforce member acting with willful neglect that is not corrected. What penalty tier applies?
- $100–$50,000 per violation (unknowing violation tier)
- $1,000–$50,000 per violation (reasonable cause tier)
- $10,000–$50,000 per violation (willful neglect — corrected tier)
- $50,000–$1,500,000 per violation (willful neglect — not corrected tier) (Correct answer)
Correct answer: $50,000–$1,500,000 per violation (willful neglect — not corrected tier)
Willful neglect violations that are not corrected within 30 days carry the highest penalty tier of $50,000 to $1,500,000 per violation per calendar year.
Under the Omnibus Rule, which of the following is a permissible use of PHI for health care operations WITHOUT individual authorization?